Gentoo Archives: gentoo-announce

From: John Helmert III <ajak@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202209-27 ] Mozilla Firefox: Multple Vulnerabilities
Date: Thu, 29 Sep 2022 14:53:18
Message-Id: YzWvKpuF+mvEuJ/T@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202209-27
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Mozilla Firefox: Multiple Vulnerabilities
9 Date: September 29, 2022
10 Bugs: #872059
11 ID: 202209-27
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in Mozilla Firefox, the
19 worst of which could result in arbitrary code execution.
20
21 Background
22 ==========
23
24 Mozilla Firefox is a popular open-source web browser from the Mozilla
25 project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/firefox < 102.3.0:esr >= 102.3.0:esr
34 < 105.0:rapid >= 105.0:rapid
35 2 www-client/firefox-bin < 102.3.0:esr >= 102.3.0:esr
36 < 105.0:rapid >= 105.0:rapid
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in Mozilla Firefox. Please
42 review the CVE identifiers referenced below for details.
43
44 Impact
45 ======
46
47 Please review the referenced CVE identifiers for details.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Mozilla Firefox ESR users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=www-client/firefox-102.3.0"
61
62 All Mozilla Firefox ESR binary users should upgrade to the latest
63 version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-102.3.0"
67
68 All Mozilla Firefox users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=www-client/firefox-105.0"
72
73 All Mozilla Firefox binary users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-105.0"
77
78 References
79 ==========
80
81 [ 1 ] CVE-2022-40956
82 https://nvd.nist.gov/vuln/detail/CVE-2022-40956
83 [ 2 ] CVE-2022-40957
84 https://nvd.nist.gov/vuln/detail/CVE-2022-40957
85 [ 3 ] CVE-2022-40958
86 https://nvd.nist.gov/vuln/detail/CVE-2022-40958
87 [ 4 ] CVE-2022-40959
88 https://nvd.nist.gov/vuln/detail/CVE-2022-40959
89 [ 5 ] CVE-2022-40960
90 https://nvd.nist.gov/vuln/detail/CVE-2022-40960
91 [ 6 ] CVE-2022-40962
92 https://nvd.nist.gov/vuln/detail/CVE-2022-40962
93
94 Availability
95 ============
96
97 This GLSA and any updates to it are available for viewing at
98 the Gentoo Security Website:
99
100 https://security.gentoo.org/glsa/202209-27
101
102 Concerns?
103 =========
104
105 Security is a primary focus of Gentoo Linux and ensuring the
106 confidentiality and security of our users' machines is of utmost
107 importance to us. Any security concerns should be addressed to
108 security@g.o or alternatively, you may file a bug at
109 https://bugs.gentoo.org.
110
111 License
112 =======
113
114 Copyright 2022 Gentoo Foundation, Inc; referenced text
115 belongs to its owner(s).
116
117 The contents of this document are licensed under the
118 Creative Commons - Attribution / Share Alike license.
119
120 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature